Checkout Bouncer

Legal

This privacy policy covers two separate things. First, what this website (checkoutbouncer.com) collects about you when you visit it or email us. Second, what the Checkout Bouncer plugin does with data on your own WooCommerce store once you install it. The two are not the same, and the second part matters for your own privacy policy.

Last updated: August 2026. Operated by NeoDigify.

The short version of this privacy policy

If you read nothing else in this privacy policy, read this.

  • We collect your email address and your message when you contact support. That is the only personal data you actively give us.
  • Our web server keeps standard access logs, which include IP addresses, for a short period.
  • We use Google Analytics to count visits and see which pages get read. It sets cookies in your browser and sends Google your IP address and the pages you view. Beyond that we run no advertising trackers and no third-party pixels.
  • We never sell, rent or trade your data. There is nobody to sell it to and we are not interested.
  • The plugin itself sends nothing to us. It talks to Google reCAPTCHA and to your own WordPress database, and that is all.

Want anything we hold about you deleted? Email support@checkoutbouncer.com and we will do it.

Who we are

This site is operated by NeoDigify, the publisher of the Checkout Bouncer plugin for WooCommerce. We are the data controller for anything collected through checkoutbouncer.com.

The single contact point for any privacy question, correction or deletion request is support@checkoutbouncer.com. A human reads that inbox.

What this website collects

Four things, and nothing else.

Emails you send us

When you email support or join the Pro waitlist, we hold your email address and whatever you chose to put in the message. Support threads often include a site URL, a plugin version and error text, because that is what it takes to answer the question.

Server logs

Like every web server, ours records each request: IP address, date and time, the page requested, the browser user agent and the response code. These logs exist to keep the site running and to spot abuse. They are not joined up into a profile of you.

Analytics

We run Google Analytics 4 on this site, added through the Google Site Kit plugin. On each page you view it sends Google your IP address, the page address, your browser and general location, and a randomly generated visitor id stored in a cookie. We use it to see which pages are read and which are ignored. We do not use it for advertising, and its advertising signals are switched off.

Google acts as our processor for this and holds the data on its own infrastructure, which means it may be transferred outside the UK and the EEA under Google’s own safeguards. Google’s handling is described in the Google Privacy Policy. If you would rather not be counted, any tracker-blocking extension or your browser’s “do not track” setting will stop it, and nothing on this site depends on analytics working.

Cookies

Google Analytics sets two cookies, _ga and _ga_<id>, which hold that random visitor id and last up to two years. WordPress itself sets cookies in a few situations: if you log in to an account here, and a temporary test cookie to check your browser accepts cookies. If you only read pages and block analytics, you are unlikely to pick up anything beyond that test cookie.

Our legal basis for holding support email is straightforward: you wrote to us and asked for help, so we have a legitimate interest in keeping the thread long enough to answer it and to recognise a follow-up. For the waitlist, the basis is your consent, which you can withdraw at any time by replying and asking to be removed.

What this website does not do

  • No advertising networks, no retargeting pixels, no social media trackers. Google Analytics is configured with its advertising features switched off.
  • No selling, renting, sharing or trading of personal data with anyone, for any price.
  • No automated decisions made about you. Google Analytics counts pages across a single visit; we do not build a profile of you beyond that and we never join it to your support emails.
  • No mailing you marketing you did not ask for. If you emailed support, you get an answer, not a newsletter.
  • No collection of payment details on this site. The plugin is free and there is nothing to buy here today.

How long we keep things

We keep the minimum for the shortest time that is still useful.

How long we keep things
WhatHow longWhy
Google Analytics recordsCookies up to 24 months; Google’s own retention for the restSo visit counts can be compared year on year
Support enquiries and repliesUp to 24 months from the last messageSo a follow-up about the same site does not start from zero
Pro waitlist email addressesUntil Pro launches, or until you ask us to remove youTo tell you once when it is available
Server access logsTypically 30 days, then rotated outUptime, debugging and abuse detection

Asking for a copy, a correction or a deletion

Email support@checkoutbouncer.com from the address you contacted us with and say what you want: a copy of what we hold, a correction, or full deletion. We aim to reply within a few working days and to act within 30 days. There is no form to fill in and no charge.

If you are in the UK or the EU, you also have the right to complain to your national data protection authority. We would rather you told us first so we can fix it.

What the plugin does on YOUR store

Everything above is about this website. This section is different, and it is the part you need for your own compliance work. Checkout Bouncer stops fake orders using Google reCAPTCHA v3. That means a Google script runs on your storefront and Google sees some information about your shoppers.

We are telling you this plainly so you can put it in your own privacy policy. Nobody wants to discover it from a customer complaint.

What gets sent to Google

reCAPTCHA v3 works by watching how a visitor behaves and returning a score from 0.0 to 1.0. To do that, Google receives the shopper’s IP address and interaction signals from the browser, which include things like mouse movement, timing, device and browser characteristics, and the page the script is running on. Google may also set cookies in the shopper’s browser as part of that scoring. This is how the product works. There is no version of reCAPTCHA that scores a visitor without seeing the visitor.

Google is the controller of that data, not us. Its handling is governed by the Google Privacy Policy and the Google Terms of Service. You supply your own free reCAPTCHA v3 keys, so the reCAPTCHA account and its data belong to you, not to NeoDigify.

One thing Checkout Bouncer never does: it does not send your orders, your customer records, your store data or your reCAPTCHA keys to NeoDigify. There is no phone-home, no usage telemetry and no remote analytics in the free plugin. The only outbound call it makes is the reCAPTCHA verification request to Google.


Where the script loads, and how to narrow it

By default, Checkout Bouncer loads the reCAPTCHA script on every front-end page of your site. That is deliberate and it is what Google recommends: v3 scores a visitor on their whole-site behaviour, so a script that only appears at the moment of checkout has almost nothing to judge. Scores get worse and real customers start failing.

You can change it. There is a setting to restrict loading to checkout screens only. That reduces the number of pages on which Google sees your visitors, at some cost to scoring accuracy. Which trade-off is right depends on your legal advice and your market. A store selling into the EU may weigh it differently from one selling only domestically. The choice is yours and the plugin respects it.


What the plugin stores in your own database

Checkout Bouncer keeps an events table inside your WordPress database so you can see what it has been doing: passes, fails and blocks, the reason for each block, and the counts behind the dashboard and the CSV export. The order-rate throttle also has to remember recent activity per IP address in order to enforce its limits: maximum orders per hour, maximum failed payments per fifteen minutes, and maximum distinct billing emails per hour.

That data sits on your server, under your control, subject to your own hosting and backup arrangements. It never reaches us. IP addresses are personal data in most jurisdictions, so if you keep those logs you should say so in your privacy policy, and you should be able to delete an individual’s records on request. The events table is yours to clear.


Cookies on your storefront

Checkout Bouncer does not set marketing cookies of its own. Google’s reCAPTCHA script, however, may set cookies in your shopper’s browser as part of scoring them. If you use a consent banner or a cookie table, reCAPTCHA belongs in it. Many privacy teams classify it as strictly necessary security tooling; others do not. That call is yours to make, and it is worth making it consciously rather than by accident.

Your responsibilities as the store owner

When you install Checkout Bouncer, you are the data controller for your shoppers. We cannot do this part for you. A short checklist:

  • Say in your own privacy policy that you use Google reCAPTCHA v3 for fraud prevention, and link Google’s privacy policy and terms.
  • State whether the script loads sitewide or only on checkout screens, so the description matches your actual setting.
  • Reflect reCAPTCHA in your cookie notice and consent flow if your jurisdiction requires it.
  • Mention that you keep security event logs, including IP addresses, and for how long.
  • Be able to answer a shopper who asks what you hold about them and to delete it when required.

The plugin documentation walks through the settings that affect each of these. Start at the docs.

Common questions

Does Checkout Bouncer send my order data to NeoDigify?

No. The plugin has no channel back to us. Orders, customers, keys and settings stay on your server. The only external request it makes is the reCAPTCHA verification call to Google.

Can I use the plugin without Google seeing anything?

No. Checkout Bouncer scores visitors with Google reCAPTCHA v3, and that scoring happens at Google. You can reduce the surface by limiting the script to checkout screens only, but you cannot use reCAPTCHA and keep Google out of it. If that is a blocker for you, this is not the right plugin, and we would rather say so than sell you something you cannot lawfully run.

Do you support hCaptcha or Cloudflare Turnstile instead?

Not today. Checkout Bouncer uses Google reCAPTCHA v3 only. There is no v2 checkbox mode, no hCaptcha and no Turnstile.

What about the Pro tier and payment data?

Pro is not released. Nothing is for sale on this site today, so we take no card details and hold no billing records. If you join the waitlist we hold only your email address, and only until Pro launches or you ask us to delete it. When Pro does arrive, this page will be updated before anything changes.

Changes to this privacy policy

If what we collect changes, or if the plugin starts doing something new with data, we update this page and change the date at the top. We do not quietly widen what we collect and hope nobody notices.

Good faith, not legal advice

This privacy policy is written in good faith and in plain English to describe what actually happens. It is not legal advice, and it is not a compliance document for your store. Your obligations depend on where you and your customers are. If you need certainty, ask a lawyer who knows your jurisdiction.

Last updated: August 2026.

A question this privacy policy did not answer?

Ask. Email support@checkoutbouncer.com and you will get a straight answer about what the plugin touches and what it does not.

See also: Terms · Features · Get the free plugin (on WordPress.org)

See which doors into your checkout are standing open